Privacy Policy
Effective September 6, 2026
1. What we collect
- Account data: email, optional name, and a hashed password, or basic profile and account identifiers received when you sign in with GitHub or Google.
- Content: chat messages, prompts, and content you choose to transmit to an AI provider; attachments and tool results; files in Browser and cloud workspaces; and application releases you intentionally publish.
- Integrations and settings: linked GitHub repository information, encrypted OAuth credentials, model and provider choices, encrypted BYO API keys, and encrypted environment variables you save for hosted applications.
- Billing data: handled by Stripe; we store your plan and subscription status, not full card numbers.
- Usage and operational data: selected models, token usage, audit events such as logins and key changes, error and performance telemetry, and limited request metadata such as IP address and browser information.
2. Browser workspaces
Project files in a Browser workspace are stored as a private project copy on our systems and synchronized to a cache in your browser for editing and preview. This lets the agent continue working when you leave or close the page without allocating a Linux sandbox. AI requests can include prompts, relevant file content, and tool results needed to answer your request. If you choose Publish, we create a separate release snapshot and serve it using the access setting you choose.
3. How we use it
We use your data to provide and secure the Service, process payments, communicate with you (e.g. verification and password-reset emails), prevent abuse, and comply with legal obligations. We do not sell your personal data or use it for targeted advertising.
4. Processors we share with
We share data with service providers as needed to operate the Service: our cloud infrastructure providers (compute, storage, and backups), Stripe (payments), Resend (transactional email), Sentry (error and performance monitoring), and GitHub or Google when you use their sign-in or integration features. Requests using the included Rigless models are normally sent to DeepSeek. When you choose or connect another AI provider or coding harness, requests are sent to that provider, which may include OpenAI, Anthropic, Google, OpenRouter, Moonshot, Zhipu, or a compatible provider you configure. Those third parties process data under their own terms and privacy policies.
5. Published applications
If you publish an application that collects information from its visitors, you decide what that application collects and how it is used. You are responsible for providing any notices and obtaining any permissions required for that collection. Information handled by the application may be processed or stored in its hosted runtime and any external services you connect to it.
6. Retention
We keep account data, chat content, Browser and cloud workspace content, application settings, and published releases while your account or the applicable feature remains active, unless you delete or unpublish them sooner. Running cloud sandboxes are ephemeral, and saved workspace snapshots are normally cleared after 30 days of inactivity with advance warning. Security and abuse-prevention audit records may be retained after other account data is deleted and are disassociated from the deleted account.
7. Deleting your data
You can delete your account at any time from Settings. Deletion removes your active account, sessions, messages, stored API keys, custom agents, Browser workspaces, cloud workspace snapshots, and published applications, and cancels any active subscription. Deleted database records may remain in routine backups until those backups rotate out: normally up to 7 days in local backups and up to 30 days in encrypted off-site backups. We may retain records required for legal or accounting purposes, such as transaction records, and disassociated security audit records.
8. Your choices and rights
You can update account settings, disconnect integrations, remove stored keys, unpublish applications, delete sessions, or delete your account using the controls in the Service. Depending on where you live, you may also have rights to access, correct, export, or delete personal data or object to certain processing. Contact us to make a request.
9. Security
We use encryption in transit, encrypt stored API keys at rest, isolate workloads in sandboxed environments, and follow least-privilege practices. No system is perfectly secure, but we work to protect your data and respond to incidents.
10. Cookies & analytics
We use Google Analytics to understand how the site is used. Because analytics cookies are not strictly necessary, we load Google Analytics only after you accept via the consent banner; declining means no analytics cookies are set and no analytics data is collected. You can change your choice at any time by clearing this site's data in your browser. Strictly necessary cookies (e.g. your login session) are always used and are not covered by the banner. We do not currently respond separately to browser Do Not Track signals; the consent choice described here controls Google Analytics.
11. Changes and contact
We may update this policy; material changes will be posted here with a new effective date. Questions or requests: privacy@rigless.ai.